Back to skill

Security audit

fun-retriever

Security checks for vulnerabilities and agentic risk

Overview

The skill is a clearly described Cointelligence.live social-agent integration with expected network, API-key, scheduling, and reporting behavior, but users should configure it carefully before enabling live actions.

Install this only if you want an agent to use a Cointelligence.live machine account. Keep the API key in an environment variable or secret manager, start with the dry-run helper, set conservative limits, and do not schedule live posting, commenting, following, or messaging unless you are comfortable with the agent acting publicly on that service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose and the referenced helper behavior are inconsistent: the skill claims autonomous participation and discovery, yet the helper only registers a machine, reads public state, and writes a scaffolded report. Such inconsistencies can conceal sensitive actions like account creation and can mislead operators about what data is collected or what actions will be taken on their behalf.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose and the referenced helper behavior are inconsistent: the skill claims autonomous participation and discovery, yet the helper only registers a machine, reads public state, and writes a scaffolded report. Such inconsistencies can conceal sensitive actions like account creation and can mislead operators about what data is collected or what actions will be taken on their behalf.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes autonomous visits, posting, commenting, voting, and friendship interactions on an external site without warning users that the agent will transmit data off-platform or may expose account, behavioral, or prompt-derived information. In an autonomous-agent skill, this omission is materially risky because operators may enable it without understanding the privacy, reputation, consent, and policy implications of unsupervised third-party interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is explicitly designed to have an autonomous agent connect to an external website, interact there, and report back activity, but the top-level description does not clearly warn users that enabling the skill causes networked participation and transmission/collection of interaction data on a third-party service. This can lead to uninformed deployment, privacy surprises, and policy/compliance issues, especially when agents may post, message, or collect content from external users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring says the script 'intentionally defaults to read-only planning,' which frames the helper as primarily non-mutating. However, the implemented register command sends a POST request to /api/machine/register, creating a remote resource rather than only planning or inspecting state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is broad and invitation-like, encouraging an autonomous agent to 'play' and 'bring back' moments from an external site without clearly defining boundaries, triggers, or prohibited actions. In an agent ecosystem, vague invocation criteria can cause over-selection of the skill and unsafe autonomous web interaction, especially since the skill is designed to engage with humans on a live platform.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The marketplace description invites an autonomous agent to 'play,' 'visit 1-3 times a day,' and 'create something' without defining clear activation boundaries, goals, or stopping conditions. That ambiguity can cause agents or users to authorize open-ended social interaction and content generation on an external site, increasing the risk of uncontrolled actions, policy drift, and unintended engagement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description promotes autonomous visits to an external social platform and actions such as creating content, commenting, voting, and making friends, but it does not warn users that the skill performs ongoing external-site interaction on their behalf. This omission can mislead deployers about the operational and reputational risks, including spammy behavior, data sharing, account misuse, and unreviewed public outputs.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · Fun-retriever-skill/fun-retriever/OWNER_SETUP.md (reported line 46)May include surrounding context.

Copy config.example.json to a private config location:

bash
mkdir -p ~/.config/fun-retriever
cp fun-retriever/config.example.json ~/.config/fun-retriever/config.json

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · OWNER_SETUP.md (reported line 46)May include surrounding context.

Copy config.example.json to a private config location:

bash
mkdir -p ~/.config/fun-retriever
cp fun-retriever/config.example.json ~/.config/fun-retriever/config.json

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes capabilities that imply network, file, and credential handling, but it does not declare any explicit tool scope or permission boundaries. That makes it easier for an agent runtime to grant broader-than-necessary access, increasing the risk of unintended network actions, local file modification, or secret exposure during autonomous operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages recurring autonomous visits, posting, commenting, following, and reporting on an external service without a prominent user-facing warning that it will perform networked social actions. In this context, autonomous external interaction is materially sensitive because it can affect third-party accounts, create reputational harm, and trigger policy or rate-limit violations if enabled without explicit informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup requires an API key to be provided and stored, but it does not prominently warn that this is a sensitive credential or explain safe handling expectations. In an autonomous skill that also reads/writes files and may use environment access, weak credential guidance increases the chance of accidental disclosure, insecure storage, or reuse in logs and reports.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest uses broad activation language like 'let your agent out to play' and 'bring back the best human-machine moments' without defining scope, triggers, or behavioral limits. In an autonomous-agent context, this can cause the model to initiate external interaction or improvisational behavior beyond user intent, increasing the risk of unsafe actions, prompt injection exposure, or unexpected data sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description explicitly encourages visiting an external site and socializing with humans and machines, but provides no privacy, consent, authentication, rate-limit, or system-impact warnings. Because this skill is designed for autonomous use on a public-facing site, missing safeguards make it easier for the agent to expose identifying information, engage in unwanted interactions, or be manipulated by untrusted external content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The setup instructions require a machine API key but do not prominently warn about secure credential handling beyond a brief note to store it outside the skill folder. Without explicit guidance, users may place the key in insecure files, logs, prompts, or version control, increasing the risk of credential leakage and unauthorized use of the machine account.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description is vague about the exact trigger conditions and operational boundaries for this skill, which can cause an autonomous agent to invoke it in unintended contexts. Because the skill involves visiting an external social site and engaging with humans, ambiguous invocation criteria increase the risk of unnecessary outbound interaction, privacy issues, or policy-unsafe behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.